Trojan

TrojanDownloader:Win32/Renos.NX removal tips

Malware Removal

The TrojanDownloader:Win32/Renos.NX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Renos.NX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Renos.NX?


File Info:

name: 3A3AD8A0B184DEA82E8B.mlw
path: /opt/CAPEv2/storage/binaries/4e20866ce59fe085517701a97e8193abc33cd076164986b386c107ef60d45787
crc32: E05465F8
md5: 3a3ad8a0b184dea82e8b339294b62272
sha1: 421c658b03ad10b2f821f2a8a0e0e50b010e458b
sha256: 4e20866ce59fe085517701a97e8193abc33cd076164986b386c107ef60d45787
sha512: 13d0f0fde676069886e3bfbc8e71c1a4dda6e30fceab86cc2666b68892bb8d10088aad9f80db8a71a29ecd0a0cfab54289ba98727d8c98ba2ef8c1fde5dd8f7e
ssdeep: 12288:HxgFbHPCNtxz1l5hwkdyMqMzNv7o+qh39NBaU5e:kylAkIf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1178409B732348DF4F83742382E6C1E69399498348AA4BC75FE087D0D947CDD8A695AC7
sha3_384: 4994a718d5d50e5dae3c42b7253906fd1bdca9b636a06060db2dede5e19ed4a20b782d4339c25c46d211fe4dac9ebf38
ep_bytes: 832d04e04500010f839d000000eb0983
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName:
FileDescription:
FileVersion: 11.0.2.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 11.0.2.0
Translation: 0x0419 0x04e3

TrojanDownloader:Win32/Renos.NX also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Renos.53
FireEyeGeneric.mg.3a3ad8a0b184dea8
McAfeeDownloader-CEW.r
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaDownloader.CodecPack.Win32.13216
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005321ee1 )
K7GWTrojan ( 005321ee1 )
Cybereasonmalicious.0b184d
VirITTrojan.Win32.Crypt.AEVG
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.JBB
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.CodecPack.sjt
BitDefenderGen:Variant.Renos.53
NANO-AntivirusTrojan.Win32.CodecPack.ikdtv
AvastWin32:Dropper-EOZ [Drp]
EmsisoftGen:Variant.Renos.53 (B)
F-SecureTrojan-Downloader:W32/Renos.GTB
DrWebTrojan.DownLoader1.42928
VIPREGen:Variant.Renos.53
TrendMicroTROJ_FAKEAV.SM3
McAfee-GW-EditionBehavesLike.Win32.Generic.fm
Trapminemalicious.high.ml.score
SophosMal/FakeAV-GX
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Renos.53
JiangminTrojanDownloader.CodecPack.bho
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan[Downloader]/Win32.CodecPack.sjt
XcitiumTrojWare.Win32.TrojanDownloader.FraudLoad.AP@2rjh9d
ArcabitTrojan.Renos.53
ZoneAlarmTrojan-Downloader.Win32.CodecPack.sjt
MicrosoftTrojanDownloader:Win32/Renos.NX
GoogleDetected
VBA32TrojanDownloader.CodecPack
ALYacGen:Variant.Renos.53
MAXmalware (ai score=89)
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_FAKEAV.SM3
RisingTrojan.Kazy!1.6834 (CLASSIC)
IkarusTrojan-Downloader.Win32.CodecPack
MaxSecureTrojan.CodecPack.Gen
FortinetW32/Codecpack.GB!tr
BitDefenderThetaGen:NN.ZelphiF.36318.yy0@a4lTzdic
AVGWin32:Dropper-EOZ [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove TrojanDownloader:Win32/Renos.NX?

TrojanDownloader:Win32/Renos.NX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment